Install a self-hosted VPN platform // Netbird

preview_player
Показать описание
Netbird is a new VPN platform that I recently installed and tested in my Homelab. It uses the fast and secure WireGuard protocol to establish point-to-point tunnels between all my devices, including cloud and HomeLab servers, PCs, Macs, and phones. With its zero-trust features and the option to self-host, Netbird offers a flexible and secure solution for connecting and protecting your devices. Join me as I install the self-hosted open-source deployment of Netbird, and I walk through all the important features and give my honest review of this exciting new platform.

References:

________________

💜 Support me and become a Fan!

💬 Join our Community!

________________

Read my Tech Documentation

My Gear and Equipment-*

________________

Timestamps:

00:00 Introduction
01:03 Netbird overview
03:20 Install self-hosted Netbird platform
12:30 How does Netbird work?
15:05 Install Netbird agent
19:05 Access Control policies
23:50 Posture checks
25:27 Network Routes and DNS
29:40 Final thoughts

________________
All links with `*` are and/or include affiliate links.
Рекомендации по теме
Комментарии
Автор

Amazing! Thank you, Christian from the whole NetBird team.

netbirdio
Автор

This thing is awesome. I'm searching for like 2 weeks now for a zero trust like get-to-home solution with which I can use domain names, and i think now I don't need to look anywhere else. Thank you for the video, I love all of yours. Thank you for the good content, keep it up!

BalintAdorjan
Автор

thank you for this video! you are always reliable! i have often used in my company solutions that you brought us in your videos

R
Автор

+1 on the comparison video. Thanks for making this one! After banging my head against the wall getting headscale to run and realising how it is still missing a bunch of features, really excited to give a fully supported foss variant a go! I have no idea why anyone would trust tailscale to run the controllers. So I am super happy that this exists! Thanks netbird team ❤❤❤

SpiritedSeeker
Автор

Nice! I initially wanted to use headscale and traefik on a small VPS, but I couldn't get it to work. NetBird was way easier to setup and instantly worked. My current setup now consists of: Raspberry Pi with Pi-hole, NPM and the NetBird client at home, and then NetBird on the VPS. Everything running in Docker containers that I manage with Portainer on the Pi (didn't need it on the VPS). This is also the first time I'm using Docker. All in all, if one is willing to invest the time to learn, it's a fun project. For the past years I only had Pi-hole and PiVPN without Docker on the same Pi and I didn't use Pi-hole's DNS, which was fine, but now everything is so much nicer.

glowingeye
Автор

The thing I love about VPN conversation is that it's nearly always in the context of privacy, on windows devices, while widgets just harvest all of your data and now copilot does the same. Hilarious.

theprecipiceofreason
Автор

Without watching the video, yet, I just wanted to chime in and say that I've tried NetBird, too, but gave up due to me not fully understanding it and it giving me a headache but I'll try it at a later stage when I got more time and I'll happily watch your video, too, to get some help and tips on that matter!

It's like you've been listening to me!

playeronthebeat
Автор

The fact that you didn't show us how to create the groups was very confusing and took me a long time to figure it out. When you are searching for a group, you can type something and hit enter, that will create the group. Thank you for this tutorial, it's really cool.

noor_codes
Автор

Hi Christian, thanks for this video. Netbird is awesome. I only use 2 internal vm´s as a peer group in the netbird server, that are installed in a separate vlan at home. So I have to define access policies in the netbird server ui and I have to create firewall rules at home in order to communicate with any other systems in my homelab (and in other vlans than the both vm´s) over these 2 vm´s. The advantage is, that I have another layer of security (if someone gets access to your admin-account, he could change the access ruls to any/any, but he can not change my firewall-rules in my homelab) and I only have to install 2 internal netbird-clients.
Unfortunately some features that you described are only available with business subscription (device posture checks), but the self hosting edition is a really cool and secure solution.

Glatze
Автор

I was breakin gmy head with this for the last 3 days and when I finally get it to work I see this video lmao. Still learned some tricks. Great stuff.

safaros
Автор

How is this even possible that you coming up with those ideas/problems that I'm currently trying to solve? It integrates with Authentik identity provider as well, that I recently set up! Nice T-shirt by the way. :D

davidszabo
Автор

Thx! Definitly need to check this and think to change from my old one ipsec l2tp vpn.

SebaPL
Автор

Thank you Christian. Since I've struggled the last couple days with installing headscale in my environment, this is really the perfect timing for me, that you released this video 👍👍😁😁

KardonGER
Автор

How to update the latest version in Linux if there is an Update notification?

fathnojoum
Автор

Netbird is great, this content is great! I cannot help but think of the Meme Man head when I look at you.

bluesquare
Автор

I would love to see a video on Zitadel, too!

ThatNateGuy
Автор

this is awesome!!! Thank you so much for this! Gonna try it right away :D

cheebadigga
Автор

A short speed comparison between other providers like tailscale and zerotier would be great.

mihirishan
Автор

Thank you for the content. Well explained as always 😊 do you think that this solution is better that tailscale or other open source solutions?

antonio.taverna
Автор

Hi christian, we tried it also on our company, but in out test every user on an domain joined laptop had the same connection and no additional authentication was needed. For us this is a no go. In a zero trust setup every user needs the own connection. Is there a setting to change this?

Greetings christoph

christophappel
visit shbcf.ru